AttachmentController.class.php 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394
  1. <?php
  2. //附件/图片等等
  3. namespace Api\Controller;
  4. use Think\Controller;
  5. class AttachmentController extends BaseController {
  6. public function index(){
  7. echo 'Attachment';
  8. }
  9. //浏览附件
  10. public function visitFile(){
  11. $sign = I("sign");
  12. $imageView2 = I("imageView2");
  13. $d = D("UploadFile") ;
  14. $ret = $d->where(" sign = '%s' ",array($sign))->find();
  15. if ($ret) {
  16. $beyond_the_quota = 0 ;
  17. $days = ceil(( time() -$ret['addtime'])/86400);//自添加图片以来的天数
  18. $adv_day_times = $ret['visit_times'] / $days ; //平均每天的访问次数
  19. $flow_rate = ( $ret['file_size'] * $ret['visit_times'] ) / $days ; //日均流量
  20. //如果是apk文件且在微信浏览器中打开
  21. if ( strpos($_SERVER['HTTP_USER_AGENT'], 'MicroMessenger') !== false && strpos($ret['real_url'] , '.apk') !== false ) {
  22. header("Content-type: text/html; charset=utf-8");
  23. echo "<head><title>温馨提示</title></head>";
  24. echo "<br><h1>微信不支持直接下载,请点击右上角“---”在外部浏览器中打开</h1>";
  25. return ;
  26. }
  27. $d->where(" sign = '%s' ",array($sign))->save(array("visit_times" => $ret['visit_times'] + 1 ,"last_visit_time"=>time()));
  28. //记录用户流量
  29. D("Attachment")->recordUserFlow($ret['uid'] , $ret['file_size']) ;
  30. //$ret['cache_url'] = '' ; //把这个变量赋值为空,禁用掉cache_url;
  31. if ($ret['cache_url']) {
  32. $url = $ret['cache_url'] ;
  33. }else{
  34. $url = $ret['real_url'] ;
  35. }
  36. $array = explode("/Public/Uploads/", $url) ;
  37. $file_path = "../Public/Uploads/".$array[1] ;
  38. $oss_open = D("Options")->get("oss_open" ) ;
  39. if (!$oss_open && file_exists($file_path) && $ret['display_name']) {
  40. $this->_downloadFile($file_path, $ret['display_name']);
  41. }else{
  42. header("location:{$url}");
  43. }
  44. }else{
  45. echo "www.showdoc.cc";
  46. }
  47. }
  48. //上传图片
  49. public function uploadImg(){
  50. $login_user = $this->checkLogin();
  51. $item_id = I("item_id/d") ? I("item_id/d") : 0 ;
  52. $page_id = I("page_id/d") ? I("page_id/d") : 0 ;
  53. if ($_FILES['editormd-image-file']['name'] == 'blob') {
  54. $_FILES['editormd-image-file']['name'] .= '.jpg';
  55. }
  56. if (!$_FILES['editormd-image-file']) {
  57. return false;
  58. }
  59. if (strstr(strip_tags(strtolower($_FILES['editormd-image-file']['name'])), ".php") || strstr(strip_tags(strtolower($_FILES['editormd-image-file']['name'])), ".htm") ) {
  60. return false;
  61. }
  62. $url = D("Attachment")->upload($_FILES , 'editormd-image-file' , $login_user['uid'] , $item_id , $page_id ) ;
  63. if ($url) {
  64. echo json_encode(array("url"=>$url,"success"=>1));
  65. }
  66. }
  67. //上传附件
  68. public function attachmentUpload(){
  69. $login_user = $this->checkLogin();
  70. $item_id = I("item_id/d") ? I("item_id/d") : 0 ;
  71. $page_id = I("page_id/d") ? I("page_id/d") : 0 ;
  72. $uploadFile = $_FILES['file'] ;
  73. // 如果附件是要上传绑定到某个页面,那么检验项目权限。如果不绑定,只是上传到自己的文件库,则不需要校验项目权限
  74. if( $page_id > 0 || $item_id > 0){
  75. if (!$this->checkItemPermn($login_user['uid'] , $item_id)) {
  76. $this->sendError(10103);
  77. return;
  78. }
  79. }
  80. if (!$uploadFile) {
  81. return false;
  82. }
  83. if (strstr(strip_tags(strtolower($uploadFile['name'])), ".php") || strstr(strip_tags(strtolower($uploadFile['name'])), ".htm") ) {
  84. $this->sendError(10100,'不支持此文件类型');
  85. return false;
  86. }
  87. $url = D("Attachment")->upload($_FILES , 'file' , $login_user['uid'] , $item_id , $page_id ) ;
  88. if ($url) {
  89. echo json_encode(array("url"=>$url,"success"=>1));
  90. }
  91. }
  92. //页面的上传附件列表
  93. public function pageAttachmentUploadList(){
  94. $login_user = $this->checkLogin();
  95. $item_id = I("item_id/d") ? I("item_id/d") : 0 ;
  96. $page_id = I("page_id/d") ? I("page_id/d") : 0 ;
  97. if (!$page_id) {
  98. $this->sendError(10103,"请至少先保存一次页面内容");
  99. return;
  100. }
  101. $return = array() ;
  102. $files = D("UploadFile")->join(" file_page on file_page.file_id = upload_file.file_id")->field("upload_file.* , file_page.item_id as item_id ,file_page.page_id as page_id ")->where("file_page.page_id = '$page_id' ")->order("file_page.addtime desc")->select();
  103. if ($files) {
  104. $item_id = $files[0]['item_id'] ;
  105. if (!$this->checkItemVisit($login_user['uid'] , $item_id)) {
  106. $this->sendError(10103);
  107. return;
  108. }
  109. foreach ($files as $key => $value) {
  110. $url = '';
  111. if($value['sign']){
  112. $url = get_domain().U("api/attachment/visitFile",array("sign" => $value['sign'])) ;
  113. }else{
  114. $url = $value['real_url'] ;
  115. }
  116. $return[] = array(
  117. "file_id"=>$value['file_id'],
  118. "display_name"=>$value['display_name'],
  119. "url"=>$url,
  120. "addtime"=> date("Y-m-d H:i:s" , $value['addtime'] ),
  121. );
  122. }
  123. }
  124. $this->sendResult($return);
  125. }
  126. //删除页面中已上传文件
  127. public function deletePageUploadFile(){
  128. $login_user = $this->checkLogin();
  129. $file_id = I("file_id/d") ? I("file_id/d") : 0 ;
  130. $page_id = I("page_id/d") ? I("page_id/d") : 0 ;
  131. $count = D("FilePage")->where(" file_id = '$file_id' and page_id > 0 ")->count() ;
  132. if($count <= 1 ){
  133. $this->deleteMyAttachment();
  134. }else{
  135. $page = M("Page")->where(" page_id = '$page_id' ")->find();
  136. if (!$this->checkItemPermn($login_user['uid'] , $page['item_id'])) {
  137. $this->sendError(10103);
  138. return;
  139. }
  140. $res = D("FilePage")->where(" file_id = '$file_id' and page_id = '$page_id' ")->delete() ;
  141. if($res){
  142. $this->sendResult(array());
  143. }else{
  144. $this->sendError(10101,"删除失败");
  145. }
  146. }
  147. }
  148. //获取全站的附件列表。给管理员查看附件用
  149. public function getAllList(){
  150. $login_user = $this->checkLogin();
  151. $this->checkAdmin(); //重要,校验管理员身份
  152. $page = I("page/d");
  153. $count = I("count/d");
  154. $attachment_type = I("attachment_type/d");
  155. $display_name = I("display_name");
  156. $username = I("username");
  157. $return = array() ;
  158. $where = ' 1 = 1 ';
  159. if($attachment_type == 1 ){
  160. $where .=" and file_type like '%image%' " ;
  161. }
  162. if($attachment_type == 2 ){
  163. $where .=" and file_type not like '%image%' " ;
  164. }
  165. if($display_name){
  166. $display_name = \SQLite3::escapeString($display_name) ;
  167. $where .=" and display_name like '%{$display_name}%' " ;
  168. }
  169. if($username){
  170. $username = \SQLite3::escapeString($username) ;
  171. $uid = D("User")->where(" username = '{$username}' ")->getField('uid') ;
  172. $uid = $uid ? $uid : -99 ;
  173. $where .=" and uid = '{$uid}' " ;
  174. }
  175. $files = D("UploadFile")->where($where)->order("addtime desc")->page($page ,$count)->select();
  176. if ($files) {
  177. foreach ($files as $key => $value) {
  178. $username = '';
  179. if($value['uid']){
  180. $username = D("User")->where(" uid = {$value['uid']} ")->getField('username') ;
  181. }
  182. $url = '';
  183. if($value['sign']){
  184. $url = get_domain().U("api/attachment/visitFile",array("sign" => $value['sign'])) ;
  185. }else{
  186. $url = $value['real_url'] ;
  187. }
  188. $return['list'][] = array(
  189. "file_id"=>$value['file_id'],
  190. "username"=>$username,
  191. "uid"=>$value['uid'],
  192. "file_type"=>$value['file_type'],
  193. "visit_times"=>$value['visit_times'],
  194. "file_size"=>$value['file_size'],
  195. "item_id"=>$value['item_id'],
  196. "page_id"=>$value['page_id'],
  197. "file_size_m"=>round( $value['file_size']/(1024*1024),3),
  198. "display_name"=>$value['display_name']?$value['display_name']:'',
  199. "url"=>$url ,
  200. "addtime"=> date("Y-m-d H:i:s" , $value['addtime'] ),
  201. "last_visit_time"=> date("Y-m-d H:i:s" , $value['last_visit_time'] ),
  202. );
  203. }
  204. }
  205. $return['total'] = D("UploadFile")->where($where)->count();
  206. $used = D("UploadFile")->where($where)->getField('sum(file_size)');
  207. $return['used'] = $used ;
  208. $return['used_m'] = round( $used/(1024*1024),3) ;
  209. $this->sendResult($return);
  210. }
  211. //删除附件
  212. public function deleteAttachment(){
  213. $login_user = $this->checkLogin();
  214. $this->checkAdmin(); //重要,校验管理员身份
  215. $file_id = I("file_id/d") ? I("file_id/d") : 0 ;
  216. $file = D("UploadFile")->where("file_id = '$file_id' ")->find();
  217. $ret = D("Attachment")->deleteFile($file_id);
  218. if ($ret) {
  219. $this->sendResult(array());
  220. }else{
  221. $this->sendError(10101,"删除失败");
  222. }
  223. }
  224. //获取我的附件列表
  225. public function getMyList(){
  226. $login_user = $this->checkLogin();
  227. $page = I("page/d");
  228. $count = I("count/d");
  229. $attachment_type = I("attachment_type/d");
  230. $display_name = I("display_name");
  231. $username = I("username");
  232. $return = array() ;
  233. $where = " uid = {$login_user['uid']} ";
  234. if($attachment_type == 1 ){
  235. $where .=" and file_type like '%image%' " ;
  236. }
  237. if($attachment_type == 2 ){
  238. $where .=" and file_type not like '%image%' " ;
  239. }
  240. if($display_name){
  241. $display_name = \SQLite3::escapeString($display_name) ;
  242. $where .=" and display_name like '%{$display_name}%' " ;
  243. }
  244. $files = D("UploadFile")->where($where)->order("addtime desc")->page($page ,$count)->select();
  245. if ($files) {
  246. foreach ($files as $key => $value) {
  247. $username = '';
  248. $return['list'][] = array(
  249. "file_id"=>$value['file_id'],
  250. "uid"=>$value['uid'],
  251. "file_type"=>$value['file_type'],
  252. "visit_times"=>$value['visit_times'],
  253. "file_size"=>$value['file_size'],
  254. "item_id"=>$value['item_id'],
  255. "page_id"=>$value['page_id'],
  256. "file_size_m"=>round( $value['file_size']/(1024*1024),3),
  257. "display_name"=>$value['display_name']?$value['display_name']:'',
  258. "url"=>get_domain().U("api/attachment/visitFile",array("sign" => $value['sign'])),
  259. "addtime"=> date("Y-m-d H:i:s" , $value['addtime'] ),
  260. "last_visit_time"=> date("Y-m-d H:i:s" , $value['last_visit_time'] ),
  261. );
  262. }
  263. }
  264. $return['total'] = D("UploadFile")->where($where)->count();
  265. $used = D("UploadFile")->where($where)->getField('sum(file_size)');
  266. $return['used'] = $used ;
  267. $return['used_m'] = round( $used/(1024*1024),3) ;
  268. $used_flow = D("Attachment")->getUserFlow($login_user['uid']) ; ; //该用户的本月使用流量
  269. $return['used_flow_m'] = round( $used_flow/(1024*1024),3) ;
  270. $this->sendResult($return);
  271. }
  272. //删除附件
  273. public function deleteMyAttachment(){
  274. $login_user = $this->checkLogin();
  275. $file_id = I("file_id/d") ? I("file_id/d") : 0 ;
  276. $file = D("UploadFile")->where("file_id = '$file_id' and uid ='$login_user[uid]' ")->find();
  277. if($file){
  278. $ret = D("Page")->deleteFile($file_id);
  279. if ($ret) {
  280. $this->sendResult(array());
  281. return ;
  282. }
  283. }
  284. $this->sendError(10101,"删除失败");
  285. }
  286. //将已上传文件绑定到页面中
  287. public function bindingPage(){
  288. $login_user = $this->checkLogin();
  289. $file_id = I("file_id/d") ? I("file_id/d") : 0 ;
  290. $page_id = I("page_id/d");
  291. $file = D("UploadFile")->where("file_id = '$file_id' and uid ='$login_user[uid]' ")->find();
  292. $page = M("Page")->where(" page_id = '$page_id' ")->find();
  293. if (!$this->checkItemPermn($login_user['uid'] , $page['item_id'])) {
  294. $this->sendError(10103);
  295. return;
  296. }
  297. $insert = array(
  298. "file_id" => $file_id,
  299. "item_id" => $page['item_id'] ,
  300. "page_id" => $page_id,
  301. "addtime" => time(),
  302. );
  303. $ret = D("FilePage")->add($insert);
  304. if( $ret){
  305. $this->sendResult(array());
  306. }else{
  307. $this->sendError(10101);
  308. }
  309. }
  310. //输出本地文件到浏览器
  311. public function _downloadFile($filename, $rename='showdoc') {
  312. //设置脚本的最大执行时间,设置为0则无时间限制
  313. set_time_limit(3000);
  314. ini_set('max_execution_time', '0');
  315. //通过header()发送头信息
  316. //因为不知道文件是什么类型的,告诉浏览器输出的是字节流
  317. header('content-type:application/octet-stream');
  318. //告诉浏览器返回的文件大小类型是字节
  319. header('Accept-Ranges:bytes');
  320. //获得文件大小
  321. $filesize = filesize($filename);//(此方法无法获取到远程文件大小),远程文件用下面get_headers方法
  322. //$header_array = get_headers($filename, true);
  323. //$filesize = $header_array['Content-Length'];
  324. //var_dump($header_array);exit();
  325. //告诉浏览器返回的文件大小
  326. header('Accept-Length:'.$filesize);
  327. //告诉浏览器文件作为附件处理并且设定最终下载完成的文件名称
  328. header('content-disposition:attachment;filename='.basename($rename));
  329. //针对大文件,规定每次读取文件的字节数为4096字节,直接输出数据
  330. $read_buffer = 4096;
  331. $handle = fopen($filename, 'rb');
  332. //总的缓冲的字节数
  333. $sum_buffer = 0;
  334. //只要没到文件尾,就一直读取
  335. while(!feof($handle) && $sum_buffer<$filesize) {
  336. echo fread($handle,$read_buffer);
  337. $sum_buffer += $read_buffer;
  338. }
  339. //关闭句柄
  340. fclose($handle);
  341. }
  342. }